ZeroHour

CVE-2021-33842

CVSS 3.1
8.8 high
EPSS
<1%p36
Published
()
Modified
Description

Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit this vulnerability, the attacker must be within the network where the device affected is located.

Vendors
circutor
Products
sge-plc1000 firmware
Weakness
CWE-565
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.